Skip to content

Add BomLens to the SBOM catalog - #142

Open
haksungjang wants to merge 2 commits into
ossf:mainfrom
haksungjang:add-bomlens
Open

Add BomLens to the SBOM catalog#142
haksungjang wants to merge 2 commits into
ossf:mainfrom
haksungjang:add-bomlens

Conversation

@haksungjang

Copy link
Copy Markdown

Adds BomLens (https://github.com/sktelecom/sbom-tools) to SBOM-Catalog/public/data.yaml.

BomLens is an open-source (Apache-2.0) SBOM generator and analyzer by SK Telecom that runs locally as a single Docker image with a CLI, web UI, and desktop app. It generates CycloneDX SBOMs from source code, containers, binaries, and firmware, and CycloneDX 1.7 ML-BOMs for HuggingFace AI models with a G7 minimum-elements conformance report. It also consumes supplier-provided CycloneDX/SPDX documents, validates and merges them, converts SPDX to CycloneDX, and produces NOTICE files plus license and known-vulnerability reports.

The entry follows the schemas/data.yaml vocabulary (verified locally) and the summary is marked AI & human reviewed.

Signed-off-by: Haksung Jang <haksung@sk.com>
@haksungjang
haksungjang requested a review from joshbressers as a code owner July 3, 2026 03:36
The repository was renamed from sktelecom/sbom-tools to sktelecom/bomlens.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant